# Logstash + xpack Authentication failure 401

**URL:** https://discuss.elastic.co/t/logstash-xpack-authentication-failure-401/117605
**Category:** Logstash
**Created:** [January 30, 2018, 11:44am UTC](https://discuss.elastic.co/t/logstash-xpack-authentication-failure-401/117605 "2018-01-30T11:44:51Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![A.Klos](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@A.Klos](https://discuss.elastic.co/u/A.Klos)
#### Post date: [January 30, 2018, 11:44am UTC](https://discuss.elastic.co/t/logstash-xpack-authentication-failure-401/117605/1 "2018-01-30T11:44:52Z")

</div>

Hi,

I installed x-pack on my 5.6.6 ELK Stack and after logstash has following errors in log:

[2018-01-30T12:26:43,208][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://logstash\_writer:xxxxxx@myserver01:9200/](http://logstash_writer:xxxxxx@myserver01:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://myserver01:9200/](http://myserver01:9200/)'"}  
[2018-01-30T12:26:43,217][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://logstash\_writer:xxxxxx@myserver01:9200/](http://logstash_writer:xxxxxx@myserver01:9200/), :path=\>"/"}  
[2018-01-30T12:26:43,223][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://logstash\_writer:xxxxxx@myserver01:9200/](http://logstash_writer:xxxxxx@myserver01:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://myserver01:9200/](http://myserver01:9200/)'"}

logstash.yml:

# Settings file in YAML

# 

# Settings can be specified either in hierarchical form, e.g.:

# 

# pipeline:

# batch:

# size: 125

# delay: 5

# 

# Or as flat keys:

# 

# pipeline.batch.size: 125

# pipeline.batch.delay: 5

# 

# ------------ Node identity ------------

# 

# Use a descriptive name for the node:

# 

# [node.name](http://node.name): test

# 

# If omitted the node name will default to the machine's host name

# 

# ------------ Data path ------------------

# 

# Which directory should be used by logstash and its plugins

# for any persistent needs. Defaults to LOGSTASH\_HOME/data

# 

path.data: /var/lib/logstash

# 

# ------------ Pipeline Settings --------------

# 

# Set the number of workers that will, in parallel, execute the filters+outputs

# stage of the pipeline.

# 

# This defaults to the number of the host's CPU cores.

# 

# pipeline.workers: 2

# 

# How many workers should be used per output plugin instance

# 

# pipeline.output.workers: 1

# 

# How many events to retrieve from inputs before sending to filters+workers

# 

# pipeline.batch.size: 125

# 

# How long to wait before dispatching an undersized batch to filters+workers

# Value is in milliseconds.

# 

# pipeline.batch.delay: 5

# 

# Force Logstash to exit during shutdown even if there are still inflight

# events in memory. By default, logstash will refuse to quit until all

# received events have been pushed to the outputs.

# 

# WARNING: enabling this can lead to data loss during shutdown

# 

# pipeline.unsafe\_shutdown: false

# 

# ------------ Pipeline Configuration Settings --------------

# 

# Where to fetch the pipeline configuration for the main pipeline

# 

path.config: /etc/logstash/conf.d

# 

# Pipeline configuration string for the main pipeline

# 

# config.string:

# 

# At startup, test if the configuration is valid and exit (dry run)

# 

# config.test\_and\_exit: false

# 

# Periodically check if the configuration has changed and reload the pipeline

# This can also be triggered manually through the SIGHUP signal

# 

# config.reload.automatic: false

# 

# How often to check if the pipeline configuration has changed (in seconds)

# 

# config.reload.interval: 3

# 

# Show fully compiled configuration as debug log message

# NOTE: --log.level must be 'debug'

# 

# config.debug: false

# 

# When enabled, process escaped characters such as \n and " in strings in the

# pipeline configuration files.

# 

# config.support\_escapes: false

# 

# ------------ Module Settings ---------------

# Define modules here. Modules definitions must be defined as an array.

# The simple way to see this is to prepend each `name` with a `-`, and keep

# all associated variables under the `name` they are associated with, and

# above the next, like this:

# 

# modules:

# - name: MODULE\_NAME

# var.PLUGINTYPE1.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE1.PLUGINNAME1.KEY2: VALUE

# var.PLUGINTYPE2.PLUGINNAME1.KEY1: VALUE

# var.PLUGINTYPE3.PLUGINNAME3.KEY1: VALUE

# 

# Module variable names must be in the format of

# 

# var.PLUGIN\_TYPE.PLUGIN\_NAME.KEY

# 

# modules:

# 

# ------------ Queuing Settings --------------

# 

# Internal queuing model, "memory" for legacy in-memory based queuing and

# "persisted" for disk-based acked queueing. Defaults is memory

# 

# queue.type: memory

# 

# If using queue.type: persisted, the directory path where the data files will be stored.

# Default is path.data/queue

# 

# path.queue:

# 

# If using queue.type: persisted, the page data files size. The queue data consists of

# append-only data files separated into pages. Default is 250mb

# 

# queue.page\_capacity: 250mb

# 

# If using queue.type: persisted, the maximum number of unread events in the queue.

# Default is 0 (unlimited)

# 

# queue.max\_events: 0

# 

# If using queue.type: persisted, the total capacity of the queue in number of bytes.

# If you would like more unacked events to be buffered in Logstash, you can increase the

# capacity using this setting. Please make sure your disk drive has capacity greater than

# the size specified here. If both max\_bytes and max\_events are specified, Logstash will pick

# whichever criteria is reached first

# Default is 1024mb or 1gb

# 

# queue.max\_bytes: 1024mb

# 

# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.acks: 1024

# 

# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint

# Default is 1024, 0 for unlimited

# 

# queue.checkpoint.writes: 1024

# 

# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page

# Default is 1000, 0 for no periodic checkpoint.

# 

# queue.checkpoint.interval: 1000

# 

# ------------ Dead-Letter Queue Settings --------------

# Flag to turn on dead-letter queue.

# 

# dead\_letter\_queue.enable: false

# If using dead\_letter\_queue.enable: true, the maximum size of each dead letter queue. Entries

# will be dropped if they would increase the size of the dead letter queue beyond this setting.

# Default is 1024mb

# dead\_letter\_queue.max\_bytes: 1024mb

# If using dead\_letter\_queue.enable: true, the directory path where the data files will be stored.

# Default is path.data/dead\_letter\_queue

# 

# path.dead\_letter\_queue:

# 

# ------------ Metrics Settings --------------

# 

# Bind address for the metrics REST endpoint

# 

# http.host: "127.0.0.1"

# 

# Bind port for the metrics REST endpoint, this option also accept a range

# (9600-9700) and logstash will pick up the first available ports.

# 

# http.port: 9600-9700

# 

# ------------ Debugging Settings --------------

# 

# Options for log.level:

# \* fatal

# \* error

# \* warn

# \* info (default)

# \* debug

# \* trace

# 

# log.level: de

path.logs: /var/log/logstash

# 

# ------------ Other Settings --------------

# 

# Where to find custom plugins

# path.plugins: []

End part 1

---

<div class="post-metadata">

### Author: ![A.Klos](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@A.Klos](https://discuss.elastic.co/u/A.Klos)
#### Post date: [January 30, 2018, 11:46am UTC](https://discuss.elastic.co/t/logstash-xpack-authentication-failure-401/117605/2 "2018-01-30T11:46:25Z")

</div>

Files in conf.d:  
10-apache-filter.conf  
10-input-beat.conf  
10-input-infoblox.conf  
10-input-json.conf  
10-input-syslogd.conf  
10-winevent-filter.conf  
20-app-elb-filter.conf  
20-app-pb-filter.conf  
20-infoblox-filter.conf  
99-output-elb.conf  
99-output-infoblox.conf  
filebeat-input.conf  
metricbeat-input.conf  
output-elasticsearch.conf

All Content in one single file (cat \* \>/tmp/bla.txt) - please ignore 88 ip and 99 ip .. it's anonymized:

filter {  
if [type] in ["apache" , "apache\_access" , "apache-access"] {  
grok {  
match =\> [  
"message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra\_fields}",  
"message" , "%{COMMONAPACHELOG}+%{GREEDYDATA:extra\_fields}"  
]  
overwrite =\> ["message"]  
}  
mutate {  
convert =\> ["response", "integer"]  
convert =\> ["bytes", "integer"]  
convert =\> ["responsetime", "float"]  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
add\_tag =\> ["apache-geoip"]  
}  
date {  
match =\> ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}  
useragent {  
source =\> "agent"  
}  
}  
if [type] in ["apache\_error","apache-error"] {  
grok {  
match =\> ["message", "[%{WORD:dayname} %{WORD:month} %{DATA:day} %{DATA:hour}:%{DATA:minute}:%{DATA:second} %{YEAR:year}] [%{NOTSPACE:loglevel}] (?:[client %{IPORHOST:clientip}] ){0,1}%{GREEDYDATA:message}"]  
overwrite =\> ["message"]  
}  
mutate  
{  
add\_field =\>  
{  
"time\_stamp" =\> "%{day}/%{month}/%{year}:%{hour}:%{minute}:%{second}"  
}  
}  
}  
}  
input {  
beats {  
port =\> 5044  
host =\> "0.0.0.0"  
}  
}

input {  
tcp {  
type =\> "syslog-srv01"  
port =\> 1516  
}  
udp {  
type =\> "syslog-srv01"  
port =\> 1516  
}  
}  
input {  
tcp {  
port =\> 5000  
codec =\> "json"  
}  
}  
input {  
udp {  
port =\> 1514  
type =\> "syslog"  
}  
tcp {  
port =\> 1514  
type =\> "syslog"  
}  
}  
filter {  
if [type] == "wineventlog" and [event\_id] == 4624 or [event\_id] == 4634 {  
drop { }  
}  
}  
filter {  
if "my-app1" in [tags] or "my-app2" in [tags] {  
grok {  
match =\> ["message" , "%{DATE\_EU:Datum} | (?[\d:\d:\d,\d]{12})" ]  
}  
mutate {  
add\_field =\> { "TIMEDATE" =\> "%{Datum} %{Uhrzeit}" }  
}  
date {  
match =\> ["TIMEDATE", "ISO8601", "dd.MM.yyyy HH:mm:ss','SSSS"]  
timezone =\> ["Europe/Berlin"]  
target =\> "@timestamp"  
}  
}  
}

filter {  
if "my-app1" in [tags] or "my-app2" in [tags] {  
grok {  
match =\> ["message" , "%{DATE\_EU:Datum} | (?[\d:\d:\d,\d]{12})" ]  
}  
mutate {  
add\_field =\> { "TIMEDATE" =\> "%{Datum} %{Uhrzeit}" }  
}  
date {  
match =\> ["TIMEDATE", "ISO8601", "dd.MM.yyyy HH:mm:ss','SSSS"]  
timezone =\> ["Europe/Berlin"]  
target =\> "@timestamp"  
}  
}  
}

filter {  
if [type] == "syslog-srv01" {  
grok {  
match =\> ["message", "%{SYSLOG5424PRI}%{SYSLOGTIMESTAMP:syslog\_timestamp} %{HOSTNAME:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}"]  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
grok {  
match =\>  
["syslog\_message","queries: client %{IP:source}#%{NUMBER:dns\_client\_key} (%{NOTSPACE:target\_work}"]  
}  
grok {  
match =\>  
["target\_work","%{URIHOST:target}):"]  
remove\_field =\> ["target\_work"]  
remove\_field =\> ["dns\_client\_key"]  
remove\_field =\> ["dns\_client\_key"]  
}  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]

```
    }

```

}

---

<div class="post-metadata">

### Author: ![A.Klos](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@A.Klos](https://discuss.elastic.co/u/A.Klos)
#### Post date: [January 30, 2018, 11:46am UTC](https://discuss.elastic.co/t/logstash-xpack-authentication-failure-401/117605/3 "2018-01-30T11:46:48Z")

</div>

output {

if "variant1-lu" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "java-variant1-lu-%{+YYYY.MM.dd}"  
}  
}  
if "variant1-de" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "java-variant1-de-%{+YYYY.MM.dd}"  
}  
}  
if "variant1-ch" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "java-variant1-ch-%{+YYYY.MM.dd}"  
}  
}  
if "variable2" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "java-variable2-%{+YYYY.MM.dd}"  
}  
}  
}  
output {  
if [type] == "syslog-srv01" {  
elasticsearch {  
index =\> "syslog-srv01-debug-%{+YYYY.MM.dd}"  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
}  
}  
}

input {  
beats {  
port =\> 5443  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

output {

if "my-app1" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-my-app1-%{+YYYY.MM.dd}"  
}  
}  
if "my-app2" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-my-app2-%{+YYYY.MM.dd}"  
}  
}  
if "tc1" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-tc1-%{+YYYY.MM.dd}"  
}  
}  
if "l-onl-a" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-onlinesysteme-apache-%{+YYYY.MM.dd}"  
}  
}  
if "ef-test-import" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-ef-test-import-%{+YYYY.MM.dd}"  
}  
}  
if "ef-test-export" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-ef-test-export-%{+YYYY.MM.dd}"  
}  
}  
if "logstash-apache-mon" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-apache-mon-%{+YYYY.MM.dd}"  
}  
}  
if [type] == "wineventlog" {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
}  
}  
if "apache-local" in [tags] {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-apache-%{+YYYY.MM.dd}"  
}  
}  
if [type] == "metricsets" {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
}  
}  
if [type] == "syslog-srv01" {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "syslog-srv01-%{+YYYY.MM.dd}"  
}  
}  
if [beat] == "metricbeat" {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> logstash\_writer  
password =\> XXXXX  
index =\> "metricbeat-%{+YYYY.MM.dd}"  
}  
}  
if [host] == "99.99.99.99" {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "test-debug-%{+YYYY.MM.dd}"  
}  
}  
if [host] == "88.88.88.88" {  
elasticsearch { hosts =\> ["[http://myserver01:9200](http://myserver01:9200)"]  
user =\> "logstash\_writer"  
password =\> "XXXXX"  
index =\> "test-debug-%{+YYYY.MM.dd}"  
}  
}  
}

logstash\_writer has following roles:

monitoring\_user, logstash\_system and remote\_monitoring\_agent.

If I user default user elastic same problem.

X-Pack seems to be working in kibana / elastic. only connection of logstash to

netstat:

Proto Recv-Q Send-Q Local Address Foreign Address State  
tcp 0 0 0.0.0.0:5666 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:5443 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:5000 0.0.0.0:\* LISTEN  
tcp 0 0 10.32.68.122:9000 0.0.0.0:\* LISTEN  
tcp 0 0 127.0.0.1:27017 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:1514 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:1516 0.0.0.0:\* LISTEN  
tcp 1 0 0.0.0.0:9200 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:80 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:5044 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:9300 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN  
tcp 0 0 127.0.0.1:6010 0.0.0.0:\* LISTEN  
tcp 0 0 127.0.0.1:9600 0.0.0.0:\* LISTEN  
tcp 0 0 0.0.0.0:5601 0.0.0.0:\* LISTEN

Any idea whats wrong?

Regards

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 27, 2018, 11:46am UTC](https://discuss.elastic.co/t/logstash-xpack-authentication-failure-401/117605/4 "2018-02-27T11:46:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
